Study guide · Core notes

CompTIA A+ Core Notes: Deep-Dive Technical Breakdown

Reference notes for the facts that CompTIA A+ questions depend on: ports and protocols, Wi-Fi standards, IP addressing, storage and RAID, memory, cloud and virtualization, Windows and Linux commands, and security procedures.

Aligned to 220-1201 & 220-1202 (V15)5 modules across Core 1 and Core 2Reviewed October 2026

How to read these notes: Items tagged Extra are not named in the V15 exam objectives but are common on the job and help you reason through related questions. Learn the objective items first. New to A+? Start with the exam overview for format, scoring, and domain weights.

Part 1 · Core 1 (220-1201)

Module 1: Networking protocols, ports, and standards

Know each port number, its transport protocol, what it does, and whether it is encrypted.

TCP/IP port reference

"Objective" means the port appears in the V15 Core 1 port list. "Encrypted" describes the protocol's default behavior.
PortProtocolTransportPurposeEncryptedScope
20, 21FTPTCPFile transfer; 20 carries data and 21 carries control commandsNoObjective
22SSH, SFTPTCPEncrypted remote command-line access; SFTP transfers files over SSHYes (SSH)Objective
23TelnetTCPLegacy text-based remote terminal; replace with SSHNoObjective
25SMTPTCPSending and relaying email between serversNo (STARTTLS optional)Objective
53DNSUDP, TCPResolves names such as www.example.com to IP addresses; TCP is used for zone transfers and large responsesNoObjective
67, 68DHCPUDPAutomatic IP configuration; 67 is the server and 68 is the clientNoObjective
69TFTPUDPSimple file transfer without authentication, used for PXE boot and device firmwareNoExtra
80HTTPTCPUnencrypted web trafficNoObjective
110POP3TCPDownloads email to one client, usually removing it from the serverNo (POP3S on 995)Objective
123NTPUDPSynchronizes clocks; time drift breaks Kerberos authentication and certificatesNoExtra
137–139NetBIOS / NetBTUDP, TCPLegacy Windows name (137), datagram (138), and session (139) servicesNoObjective
143IMAPTCPAccesses mail that stays on the server and syncs across devicesNo (IMAPS on 993)Objective
161, 162SNMPUDPNetwork device monitoring; 161 for queries and 162 for trapsOnly SNMPv3Extra
389LDAPTCP, UDPQueries directory services such as Active DirectoryNo (LDAPS on 636)Objective
443HTTPSTCPWeb traffic secured with TLSYes (TLS)Objective
445SMB / CIFSTCPWindows file and printer sharingOptional (SMB 3.x)Objective
514SyslogUDPSends system events to a central logging serverNoExtra
636LDAPSTCPLDAP secured with TLSYes (TLS)Extra
993IMAPSTCPIMAP secured with TLSYes (TLS)Extra
995POP3STCPPOP3 secured with TLSYes (TLS)Extra
3389RDPTCP, UDPMicrosoft graphical remote desktopYes (TLS)Objective

Exam tip: TCP is connection-oriented, with a handshake, acknowledgments, and retransmission. UDP is connectionless and faster but does not guarantee delivery. Services that need quick, small exchanges, such as DHCP, TFTP, NTP, SNMP, and most DNS lookups, use UDP.

Wireless networking standards

Speeds are theoretical maximums. Real-world throughput is much lower.

StandardFrequencyMax speedWhat to remember
802.11a5 GHz54 MbpsLegacy; less interference than 2.4 GHz but shorter range
802.11b2.4 GHz11 MbpsLegacy; prone to interference from microwaves, cordless phones, and Bluetooth
802.11g2.4 GHz54 MbpsBackward-compatible with 802.11b
802.11n (Wi-Fi 4)2.4 GHz and 5 GHz600 MbpsIntroduced MIMO (multiple-input multiple-output) and channel bonding
802.11ac (Wi-Fi 5)5 GHz~6.9 GbpsAdded downlink MU-MIMO and standardized beamforming
802.11ax (Wi-Fi 6 / 6E)2.4, 5, and 6 GHz (6 GHz is Wi-Fi 6E)~9.6 GbpsIntroduced OFDMA for dense environments; requires WPA3 on 6 GHz
802.11be (Wi-Fi 7) Extra2.4, 5, and 6 GHz~46 Gbps320 MHz channels and multi-link operation (MLO)

Channel planning: In the 2.4 GHz band, use channels 1, 6, and 11 in North America because they do not overlap. The 5 GHz and 6 GHz bands offer many more non-overlapping channels, and wider channels (40, 80, or 160 MHz) increase speed but reduce the number of usable channels.

IP addressing quick reference

IPv4 addresses are 32 bits, written as four decimal octets. IPv6 addresses are 128 bits, written as eight groups of hexadecimal, and consecutive groups of zeros can be shortened once with ::.

Address typeRange
Private (Class A)10.0.0.0/8
Private (Class B)172.16.0.0/12 (172.16–172.31)
Private (Class C)192.168.0.0/16
APIPA169.254.0.0/16: the client could not reach a DHCP server
Loopback127.0.0.1 (IPv4), ::1 (IPv6)
IPv6 link-localfe80::/10, similar in purpose to APIPA
IPv6 global unicast2000::/3, publicly routable
CIDRSubnet maskUsable hosts
/8255.0.0.016,777,214
/16255.255.0.065,534
/24255.255.255.0254
/25255.255.255.128126
/26255.255.255.19262
/27255.255.255.22430
/28255.255.255.24014

Usable hosts equal 2(32 − prefix) − 2, because the network and broadcast addresses cannot be assigned. A client with a 169.254.x.x address almost always points to a DHCP problem: check the cable, the switch port, the DHCP server or scope, and then run ipconfig /release and ipconfig /renew.

Module 2: Hardware architecture and storage

Interfaces set the speed ceiling; RAID levels set the balance between speed, capacity, and fault tolerance.

Storage interfaces and performance

  • SATA III: 6 Gbps link, about 550–600 MB/s in practice. Used by 2.5-inch SSDs, HDDs, and M.2 SATA drives.
  • NVMe: a protocol designed for flash storage that runs over PCIe lanes with many parallel command queues, giving far lower latency than SATA's AHCI.
  • Typical PCIe x4 NVMe drive speeds: Gen 3 up to ~3,500 MB/s, Gen 4 up to ~7,000–7,500 MB/s, Gen 5 up to ~14,000 MB/s.
  • SAS: enterprise drive interface with dual ports and higher reliability, common in servers.

Form factors and the M.2 trap

  • M.2 is a form factor, not a speed. An M.2 slot can support SATA, NVMe, or both, so check the motherboard manual.
  • Common M.2 sizes are written as width and length in millimeters, such as 2280 (22 mm × 80 mm).
  • mSATA is an older, smaller SATA form factor used in some laptops.
  • HDDs come in 3.5-inch (desktop) and 2.5-inch (laptop) sizes; spindle speeds such as 5,400 and 7,200 RPM affect performance.
N is the number of drives. Capacity assumes drives of equal size.
RAID levelMethodMinimum drivesUsable capacityFault tolerance
RAID 0Striping2100% (N drives)None; one failure loses all data
RAID 1Mirroring250%Survives one drive failure in a two-drive mirror
RAID 5Striping with distributed parity3N − 1 drivesSurvives one drive failure
RAID 6Striping with dual parity4N − 2 drivesSurvives two simultaneous drive failures
RAID 10 (1+0)Striped mirrors4 (even numbers)50%Survives one failure per mirror pair

RAID is not a backup. It protects against drive failure, not accidental deletion, ransomware, or a failed controller. Keep separate backups, ideally following the 3-2-1 rule.

System RAM architecture

DDR generations are not interchangeable. The key notch prevents installing the wrong module.

TypeDIMM pins (desktop)SODIMM pins (laptop)VoltageKey features
DDR32402041.5 V (1.35 V for DDR3L)Legacy systems
DDR42882601.2 VOne 64-bit channel per module
DDR5288 (notch in a different position)2621.1 VTwo independent 32-bit subchannels per module, on-die ECC, and an on-module power management IC

ECC vs. non-ECC RAM

ECC (error-correcting code) modules store extra bits, typically 72 bits per 64 bits of data, so the memory controller can detect and correct single-bit errors as they happen. ECC is standard in servers and workstations and requires both a compatible CPU and motherboard.

DDR5 on-die ECC corrects errors only inside each memory chip. A standard DDR5 module is not ECC RAM.

Channel configurations

Dual-channel and multi-channel memory are features of the CPU's memory controller and motherboard. Install matched modules in the slots the manual specifies, usually the same-colored slots, to enable them. Mismatched sizes or wrong slots can fall back to single-channel mode and reduce bandwidth.

Module 3: Virtualization and cloud computing

Know who manages what in each service model and how each deployment model is shared.

Service modelProvider managesCustomer managesExamples
IaaS (Infrastructure as a Service)Physical hardware, networking, storage, and virtualizationOperating system, middleware, runtime, applications, and dataAWS EC2, Azure Virtual Machines
PaaS (Platform as a Service)Everything in IaaS plus the operating system and runtimeApplications and dataAWS Elastic Beanstalk, Heroku, Google App Engine
SaaS (Software as a Service)The entire application stackApplication settings, user accounts, and dataMicrosoft 365, Google Workspace, Salesforce

Deployment models

  • Public: multitenant infrastructure owned by a provider and delivered over the internet.
  • Private: single-tenant cloud dedicated to one organization, on premises or hosted.
  • Hybrid: public and private clouds connected so workloads and data can move between them, typically over a VPN or a dedicated link.
  • Community: shared by several organizations with common compliance or mission requirements.

Cloud characteristics

  • Elasticity: resources scale up and down automatically with demand.
  • Metered utilization: you pay for what you use, including ingress and egress data transfer.
  • Shared vs. dedicated resources: multitenant hardware vs. hardware reserved for one customer.
  • Availability and file synchronization across devices and locations.

Hypervisor classifications

The question to ask: is there a host operating system underneath the hypervisor?

Type 1 · Bare metal

Runs directly on hardware

Installs directly on the physical server without a general-purpose host operating system. It offers low overhead and high performance for enterprise and data center use.

  • VMware ESXi
  • Microsoft Hyper-V
  • Proxmox VE (KVM-based)
Type 2 · Hosted

Runs as an application

Installs on top of an existing operating system such as Windows, macOS, or Linux. It has more overhead but is ideal for testing, training, sandboxing, and running legacy software on a desktop.

  • Oracle VirtualBox
  • VMware Workstation
  • Parallels Desktop

Requirements: Virtualization needs CPU support (Intel VT-x or AMD-V) enabled in BIOS/UEFI, enough RAM and storage for every guest, and a virtual network configuration. Containers are different: they share the host's kernel instead of running a full guest operating system.

Part 2 · Core 2 (220-1202)

Module 4: Operating system administration and CLI tools

Windows commands are run in Command Prompt. Commands marked Extra are not in the V15 list but are standard repair tools.

# Network and connectivity diagnostics
ipconfig /all              # Full TCP/IP configuration, MAC address, DHCP lease, and DNS servers
ipconfig /release          # Releases the current DHCP lease
ipconfig /renew            # Requests a new DHCP lease
ipconfig /flushdns         # Clears the local DNS resolver cache
ping -t <target>           # Pings continuously until stopped with Ctrl+C
tracert <target>           # Shows each hop and its latency on the path to a destination
pathping <target>          # Combines tracert with packet-loss statistics per hop
nslookup <domain>          # Queries DNS for a domain's records
netstat -ano               # Lists connections, listening ports, and owning process IDs (PIDs)
net use Z: \\server\share  # Maps a network drive to a drive letter

# Disk and system file integrity
sfc /scannow               # Scans and repairs protected Windows system files
DISM /Online /Cleanup-Image /RestoreHealth   # Extra: repairs the component store that sfc relies on
chkdsk C: /f               # Fixes file system errors
chkdsk C: /r               # Locates bad sectors and recovers readable data (includes /f)
diskpart                   # Interactive partition and volume management

# Policy, users, and processes
gpupdate /force            # Reapplies all Group Policy settings immediately
gpresult /r                # Summarizes the Group Policy Objects applied to the user and computer
whoami                     # Shows the signed-in user account
net user                   # Lists or manages local user accounts
tasklist                   # Extra: lists running processes and their PIDs
taskkill /PID <id> /F      # Extra: forcibly ends a process by PID
<command> /?               # Shows help for any command

Repair order: If sfc /scannow reports files it cannot fix, run DISM /Online /Cleanup-Image /RestoreHealth to repair the source image, then run sfc /scannow again.

Core Linux terminal commands

For more practice, see the Linux CLI Fundamentals topic.

CommandWhat it does
ls -l, pwd, cdLists files with permissions, prints the current directory, and changes directories
cp, mv, rmCopies, moves or renames, and deletes files
chmod 755 <file>Sets permissions: owner read, write, and execute (7); group and others read and execute (5)
chown <user>:<group> <file>Changes a file's owner and group
grep "<term>" <file>Searches text for lines that match a pattern
find / -name <file>Searches the file system for files by name and other attributes
sudo, suRuns one command with root privileges, or switches to another user account
apt, dnfInstalls and updates packages on Debian/Ubuntu and Fedora/RHEL systems
ps aux, topLists all processes, or shows a live view of CPU and memory use
kill -9 <PID> ExtraSends SIGKILL to force a process to stop
df -h, du -shShows free disk space per file system, and the size of a directory
ip a, ping, dig, curl, tracerouteShows interfaces and addresses, tests reachability, queries DNS, fetches URLs, and traces routes
fsck, mountChecks and repairs a file system, and attaches a file system to a directory
man, cat, nanoOpens a command's manual, prints file contents, and edits text files

Key files: /etc/passwd stores user accounts, /etc/shadow stores password hashes, /etc/hosts maps names to IPs locally, /etc/fstab defines file systems mounted at boot, and /etc/resolv.conf lists DNS servers.

Module 5: Security fundamentals and threat response

Social engineering targets people rather than systems. Learn the delivery method that defines each attack.

AttackHow it worksBest defense
PhishingMass emails that lure victims into clicking malicious links or entering credentialsUser training, email filtering, MFA
Spear phishingPhishing tailored to a specific person or organizationVerify unusual requests through a second channel
WhalingSpear phishing aimed at executives such as CEOs and CFOsExecutive awareness training, payment approval workflows
Vishing / SmishingSocial engineering by voice call (vishing) or SMS text message (smishing)Never share credentials by phone or text; call back on a known number
QR code phishingA QR code leads to a malicious site or downloadCheck the URL before opening; avoid codes from untrusted sources
Business email compromise (BEC)A compromised or spoofed business account requests payments or dataOut-of-band verification of payment changes
Pharming ExtraPoisoned DNS or a modified hosts file silently redirects users to a fake siteSecure DNS, check certificates, protect the hosts file
Tailgating / piggybackingFollowing an authorized person through a secured doorAccess control vestibules, badge policies, security guards
Shoulder surfingWatching someone enter passwords or view sensitive dataPrivacy screens, awareness of surroundings
Dumpster divingSearching discarded materials for sensitive informationShredding and secure disposal policies
Evil twinA rogue access point that imitates a legitimate SSIDWPA3 or WPA2-Enterprise, VPN on public Wi-Fi

Wireless security protocols and authentication

Choose the strongest protocol every device supports. WEP and WPA (TKIP) are obsolete.

Wi-Fi encryption

  • WPA2: uses AES (CCMP). Personal mode uses a pre-shared key; Enterprise mode authenticates each user through 802.1X and RADIUS.
  • WPA3: replaces the pre-shared key handshake with SAE, which resists offline password guessing and adds forward secrecy. It is required for 6 GHz Wi-Fi.
  • TKIP: the legacy WPA cipher; avoid it and choose AES.

Authentication services

  • RADIUS (UDP 1812/1813): centralized AAA for Wi-Fi, VPN, and network access; encrypts only the password.
  • TACACS+ (TCP 49): Cisco-developed AAA, encrypts the entire payload, and separates authentication, authorization, and accounting. Common for network device administration.
  • Kerberos (port 88): ticket-based authentication used by Active Directory. Requires accurate time synchronization.

CompTIA malware removal procedure

Core 2 tests this sequence for a SOHO computer. Scenario questions often ask which step comes first or next, so learn the order and the reason for each step.

  1. Investigate and verify malware symptoms. Look for pop-ups, browser redirection, unknown processes, disabled security tools, and altered or missing files.
  2. Quarantine the infected system. Disconnect it from the network (Ethernet, Wi-Fi, and Bluetooth) and stop using removable media with it, so the malware cannot spread.
  3. Disable System Restore in Windows Home. Infected restore points could otherwise reintroduce the malware later.
  4. Remediate the infected system. Update anti-malware definitions, scan and remove threats using safe mode or a preinstallation environment, and reimage or reinstall the operating system if the infection cannot be removed reliably.
  5. Schedule scans and run updates. Apply operating system and application updates, and confirm that real-time protection and scheduled scans are on.
  6. Enable System Restore and create a restore point in Windows Home. This creates a clean recovery baseline.
  7. Educate the end user. Explain how the infection likely happened and how to recognize phishing and unsafe downloads.

A common trap: updating anti-malware definitions is part of remediation (step 4), after the system is already quarantined and System Restore is disabled. Do not choose it as the first step.

Frequently asked questions

Are these notes for 220-1101/1102 or 220-1201/1202?

These notes follow the current V15 objectives for Core 1 (220-1201) and Core 2 (220-1202). Most of the material also applies to the retired 220-1101 and 220-1102 exams.

Do I need to memorize ports outside the official list?

Learn the 14 port entries in the official Core 1 list first. Ports marked Extra, such as 69, 123, 161/162, 514, 636, 993, and 995, are useful on the job and help with related questions, but they are not listed in the V15 objectives.

What is the difference between ECC RAM and DDR5 on-die ECC?

ECC RAM adds extra data bits so the memory controller can detect and correct errors on the module, and it requires motherboard and CPU support. DDR5 on-die ECC only corrects errors inside each memory chip, so a standard DDR5 module is not ECC RAM.

Continue the CompTIA A+ study path

Flashcards and practice exams are still being prepared.

CompTIA A+ hub →
Available

Overview

Exam format, scoring, domain weights, V15 changes, and exam strategy.

Available · You are here

Core Notes

Technical reference notes for networking, hardware, cloud, operating systems, and security.

In preparation

Flashcards & Memory Notes

Focused recall prompts for ports, standards, commands, and other high-yield facts.

In preparation

Practice Exams

Original practice questions with explanations and a clearly stated scope. No release date is promised.

Related Tools

Useful companions while you study.

All study topics →